
Session recap from Realize LIVE Americas 2026 in Detroit.
At this year’s Realize LIVE Americas in Detroit, Radek Krotil, Head of Products at Nextedy, opened with a claim most aerospace teams recognize the hard way: safety programs don’t break during design — they break in the audit, when the evidence chain the authority asks for was never built. His session showed the way out: make risk the centerpiece of the development process, in Polarion.
In Brief
Aerospace safety programs usually discover traceability gaps at SOI 3 and 4 audits — when the design is done and rework is most expensive.
The fix presented: make risk the integrator — one Polarion data model from hazard assessment and FMEA through risk controls to requirements and verification evidence.
Live SOI stage-gate dashboards with cross-cutting gap detection surface missing links the moment they appear, not at audit time.
Everything shown runs on Nextedy Risksheet and PowerSheet on top of Polarion — and is available as a free trial with a complete aerospace sample project.
Watch the full session recording:
Programs Don’t Fail in Design — They Fail in the Audit
Audit intensity in aerospace keeps increasing, and authorities want evidence chains, not buckets of documents. Yet traceability gaps typically surface at Stage of Involvement (SOI) 3 and 4 — during final verification, when the design is complete and rework is at its most expensive.
The root cause is a fragmented tool landscape: requirements live in Polarion, safety analyses in specialized best-of-breed tools, and the two are synchronized by hand through files and spreadsheets. Somewhere along that path, safety requirements lose their connection to the risks that justify them — and that is exactly the link the auditor asks for.
Risk Is the Integrator, Not a Sidecar
The heart of the session is a second, risk-driven V laid over the classic development V-model. It starts from the Functional Hazard Assessment (FHA) at aircraft level, classifies failure conditions into Design Assurance Levels (DAL A–E) — calculated automatically from the classification — and drills down into system-level and component-level FMEA. Unacceptable risks are mitigated by risk controls that translate into safety-related system requirements, get decomposed into the design, and are closed by verification evidence on the way back up the V.
It is one data model in Polarion covering six standards without duplication: ARP 4761 (safety assessment), ARP 4754A (system development assurance), DO-178C (software), DO-254 (hardware), DO-326A (security), and MIL-STD-882E (system safety, with its broader hazard scope covering environment, human factors, and procedures). Functional safety and cybersecurity are deliberately linked in the model — a successful cyberattack can very well become a safety event.
The SOI Stage Gate Dashboard: Audit Readiness as Live Data
The entry point to the process is the SOI Stage Gate Dashboard, a live Polarion report. It shows gate readiness per SOI stage and counts the traceability backbone across the whole chain — in the demo dataset, 18 hazards → 260 failure modes → 224 risk controls → 34 system requirements → 52 test cases. Cross-cutting gap detection names problems the way an auditor would: hazards without an inbound mitigates link, system requirements without a verifying test case, compliance objectives without a resolution.
Every number is a live query against project data. Click a finding and Polarion opens the exact view where you can fix it — shift-left, applied to traceability. Shifting gap detection from SOI 4 to SOI 2 is, in Radek’s words, the single highest-leverage change most programs can make today.
From Hazard to Evidence in Editable Sheets
Risksheet drives the assessments: FHA per system function and flight phase with automatic DAL calculation, FMEA with severity, occurrence, detection and a calculated action priority, and risk controls created inline — or found with an AI-assisted search that knows which system, function, and failure condition you are working on.
PowerSheet authors multi-level traceability: every blank cell is a traceability gap, smart routing knows where a new test case or requirement belongs, the whole requirements-to-verification V fits in a single view, and a live compliance matrix tracks 39 objectives across five standards — DO-178C (16), DO-254 (8), plus ARP 4754A, ARP 4761, and MIL-STD-882E with per-DAL status, grouped by SOI gate, recalculated every time it is opened. As Radek put it: the compliance matrix is not a deliverable — it is a query.
A common cause analysis — completes the picture in three parts: zonal safety analysis for physical proximity risks such as fire or cooling, particular risk analysis for external threats such as lightning strike, HIRF, or ice ingestion, and common mode analysis, which confirms that systems assumed to be independent do not share a failure mechanism.
Honest Gaps: What Stays Outside Polarion
Some disciplines rightly stay in specialist tools — fault tree analysis and MC/DC coverage for the most critical software among them. The goal is not to force everything into Polarion, but to keep those analyses orchestrated and traceable from the single source of truth — down to requirement-to-code-line traceability. The template is equally honest about its own maturity: the final certification submission package is still on the roadmap. The goal is not to replace every engineering tool; it is to keep the certification chain connected.
Key Takeaways
Risk is the integrator. Most safety requirements originate in risk. Put risk assessment at the center of your development process, not beside it.
Compliance is built, not collected. Live reports over a single source of truth surface gaps while you still have the context to close them cheaply.
Know the boundary. Be explicit about what lives in external tools and how its traceability feeds back into Polarion.
Try It Yourself: the 30-Day Trial
Everything shown in the session ships with the trial: the flight control computer reference dataset — DAL A, three subsystems, eight components — with pre-filled FHA, SFMEA, DFMEA, and CCA, the live SOI Stage Gate Dashboard, the compliance matrix, more than sixteen pre-wired link roles, and documentation guides for each SOI gate. It is available as a free 30-day trial: fill in one form and your own demo project is ready in about a minute.
Want to map this to your own program? Book a 1:1 with Radek.
